Incorrect permission assignment for critical resource in Siemens products - CVE-2021-31894

 

Incorrect permission assignment for critical resource in Siemens products - CVE-2021-31894

Published: July 14, 2021


Vulnerability identifier: #VU54870
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-31894
CWE-ID: CWE-732
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Siemens
Affected software:
SIMATIC PCS 7
SIMATIC PDM
SIMATIC STEP 7
SINAMICS STARTER

Detailed vulnerability description

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to incorrect permission assignment for critical resource. A local user can change the content of certain metafiles and subsequently manipulate parameters or the behavior of devices that would be later configured by the affected software.


How to mitigate CVE-2021-31894

Install updates from vendor's website.

Sources